Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JBL Go 2 安全漏洞
Vulnerability Description
JBL Go 2是日本JBL公司的一个全功能的便携式防水蓝牙音箱。 JBL Go 2 2021-08-09及之前版本存在安全漏洞。远程攻击者通过望远镜和光电传感器(也称为“萤火虫”攻击)从设备上的LED恢复语音信号。扬声器的电源指示LED直接连接到电源线,因此,设备电源指示LED的强度与功耗相关。扬声器播放的声音会影响其功耗,因此也与LED的光强度相关。通过分析从指向扬声器电源指示灯LED的光电传感器获得的测量值,可以恢复扬声器播放的声音
CVSS Information
N/A
Vulnerability Type
N/A